Loading...

Advancing Cybersecurity: The Latest enhancement in Phishing-Resistant Authentication

Advancing Cybersecurity: The Latest enhancement in Phishing-Resistant Authentication

Today, I’m excited to share with you several new developments in the journey towards phishing-resistant authentication for all users!  This isn’t just essential for compliance with Executive Order 14028 on Improving the Nation's Cybersecurity but is increasingly critical for the safety of all the orgs and users who bet on digital identity.

 

TL;DR? Here’s the cheat sheet!

 

  • Microsoft Authenticator announces phishing-resistant passkey support.
  • Microsoft Authenticator is FIPS 140-3 compliant on all platforms.
  • More configuration options for PIV/CAC authentication.
  • FIDO2 support for iOS and MacOS applications.
  • Managed policies help you with “secure by design, secure by default.”

 

Details below!

 

Microsoft Authenticator is becoming phishing-resistant!

 

As announced at Ignite 2023, in the first half of 2024, Microsoft Entra ID users will soon be able to register and sign in with device-bound passkeys managed in the Microsoft Authenticator app. This is a cost-effective, phishing-resistant credential available to anyone with the Authenticator app! Passkeys provide you with the latest and greatest security enhancements that will come to the FIDO standard over the next many years – and Authenticator integration lets you take advantage of the security innovations and advanced features Authenticator provides.

 

Figure 1: Passkey managed in the Microsoft Authenticator appFigure 1: Passkey managed in the Microsoft Authenticator app

 

To further enhance Microsoft Authenticator and help customers meet compliance requirements, the Authenticator App on Android is now FIPS-140 compliant.

 

Beginning with version 6.2310.7174, Microsoft Authenticator for Android is compliant with Federal Information Processing Standard (FIPS 140-3) for all Microsoft Entra authentications using phishing-resistant device-bound passkeys, push multifactor authentications (MFA), passwordless Phone Sign-In (PSI), and time-based one-time passcodes (TOTP). For organizations using Intune Company Portal, install version 5.0.6043.0 in addition to the latest version of the Authenticator for FIPS compliance.

 

The Microsoft Authenticator app on iOS is already FIPS-140 compliant, as announced in December of 2022. Learn more about FIPS 140 complaint for the Microsoft Authenticator app.

 

Improved configurability for organizations that uses PIV / CAC

 

In the last year since we announced the General Availability of Certificate-based Authentication (CBA), we’ve seen an increase of over 850% in Entra ID CBA usage for US Government customers. CBA helps our customers in their Zero Trust journey, migrating from on-premises IdPs such as AD FS, while continuing to provide familiar end user experience using PIV / CAC.

 

We continue our investments in cloud-based CBA with recently added capabilities that allow you to tailor authentication policies by certificate and resource type, as well as user group. You can now select certificate strength for different users, use CBA with other methods for multifactor or step-up authentication, and set high affinity (strong) binding for either the entire tenant or by user group.

 

 

Figure 2: Configure certificate-based authentication binding policy ruleFigure 2: Configure certificate-based authentication binding policy rule

 

 

Learn more about our latest enhancements to Microsoft Entra certificate-based authentication.

 

Additional phishing-resistant authentication options for mobile: FIDO2 support for iOS and macOS applications

 

In the summer of 2023, we announced support for FIDO2 authentication on iOS and macOS web browsers. Today, we’re excited to announce the public preview of FIDO2 authentication on iOS and macOS . With this release, users who have Microsoft Authenticator installed on iOS or Microsoft Intune Company Portal installed on macOS can sign into Microsoft applications using a FIDO2 security key. This feature is available now on iOS and will be available early next year on macOS.

 

FIDO2 authentication is also available in MSAL-enabled third-party apps on iOS and macOS that meet the requirements listed in Support passwordless authentication with FIDO2 keys in apps you develop.

 

Learn more about the supported platforms here.

 

Adopting secure defaults, aligned with “Secure by design, secure by default” approach outlined by CISA

 

Earlier this month, Microsoft announced the Secure Future Initiative. As part of this initiative, we will start Auto-rollout of Conditional Access policies. These initiatives align with the “Secure by design, Secure by default” approach called out by The Cybersecurity and Infrastructure Security Agency (CISA), to ensure consumers can trust the safety and integrity of the technology that they use every day.

 

We believe that tackling cybersecurity challenges is a collective effort. We're dedicated to collaborating closely with government agencies, security experts, and the broader community to strengthen our collective defenses against cyber threats. Our aim is to provide government customers with the tools and knowledge they need to stay ahead of evolving risks.

 

Our recent releases and ongoing commitment to enhancing cybersecurity will support our broad set of customers, including the U.S. government customers who are working to meet the Executive Order. Together, we can build a more secure digital future.

 

Best regards,

Alex Weinert

 

 

Learn more about Microsoft Entra: 

 

Published on:

Learn more
Azure Active Directory Identity Blog articles
Azure Active Directory Identity Blog articles

Azure Active Directory Identity Blog articles

Share post:

Related posts

Sync identities from Rippling to Microsoft Entra ID

Today, we’re thrilled to announce that customers using Rippling HCM can now automatically provision users to on-premises Active Directory and ...

1 year ago

Microsoft Entra ID Governance for government

I’m pleased to announce that as of November 1, 2024, Microsoft Entra ID Governance is available for federal agencies, state and local governme...

1 year ago

Update to security defaults

As part of the Secure Future Initiative, we’ve evolved our security approach to align with three security principles: secure by design, secure...

1 year ago

Meet Microsoft Entra at Ignite 2024: November 18-22

Microsoft Ignite is just around the corner, taking place from Monday, November 18, 2024 through Friday, November 22, 2024, in Chicago, Illinoi...

1 year ago

Manage Microsoft Entra ID role assignments with Microsoft Entra ID Governance

I’m excited to announce that we now support Microsoft Entra role assignments in Microsoft Entra ID Governance's Entitlement Management feature...

1 year ago

The latest enhancements in Microsoft Authenticator

Hi folks,   I'm thrilled to announce three major Microsoft Entra ID advancements that will help you protect your users with phishing-resi...

1 year ago

Microsoft Security announcements and demos at Authenticate 2024

The Microsoft Security team is excited to connect with you next week at Authenticate 2024 Conference, taking place October 14 to 16 in Carlsba...

1 year ago

What's new in Microsoft Entra - September 2024

We’re excited to announce the general availability of Microsoft Entra Suite—one of the industry’s most comprehensive secure access solutions f...

1 year ago

Explore the key benefits of Microsoft Entra Private Access

The traditional network security models are becoming increasingly ineffective in a world where remote work and cloud services are the norm. Co...

1 year ago

Join us at the Microsoft Entra Suite Showcase!

This fall, we are bringing the Microsoft Entra Suite Showcase to cities worldwide. Join us to explore how our latest advancements in secure id...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.